$10,000 Mac hack affects Windows too

April 24, 2007, 02:44 PM —  IDG News Service — 

The bug that helped security researcher Dino Dai Zovi claim a $10,000 prize at last week's CanSecWest security conference affects Windows systems too.

That's because the flaw that Dai Zovi exploited actually lies in the way Apple's QuickTime Media Player works with the Java programming language, according to Terri Forslof, manager of security response at 3Com Corp.'s TippingPoint division, which put up the $10,000 prize. QuickTime runs on both Windows and the Mac.

When first reported, last week Dai Zovi's bug was thought to lie in Apple's Safari browser, a standard component of Mac OS X. But users of Firefox -- which supports QuickTime on both Windows and the Mac -- are also at risk, Forslof said Tuesday.

In terms of seriousness, the bug is comparable to the animated cursor vulnerability that was recently patched in Windows, Forslof said. The bug "is the equivalent to a 'click and you're owned' vulnerability," she said.

TippingPoint disclosed the flaw to Apple on Monday, but there is still no word on when it will be patched. Because the flaw has not been publicly disclosed, it is not considered to be a significant threat to QuickTime users.

Dai Zovi disclosed the flaw to TippingPoint as part of a contest set up by CanSecWest organizers to see how easy it was to take control of a Mac. "You see a lot of people running OS X saying it's so secure and frankly Microsoft is putting more work into security than Apple has," said Dragos Ruiu, the principal organizer of CanSecWest, speaking at the show in Vancouver last week.

Initially, contestants were invited to try to access one of two Macs through a wireless access point without any programs running. No attackers managed to do so, and so conference organizers allowed participants to try to get in through the browser by sending URLs (uniform resource locators) via e-mail.

Dai Zovi, who lives in New York, sent a URL that exposed the hole. Since the contest was only open to attendees in Vancouver, he sent it to a friend who was at the conference and forwarded it on.

Though CanSecWest's Ruiu said that Apple has been heavy handed in its past dealings with security researchers, Dai Zovi said that has not been his experience. "I have yet to hear anything from Apple besides their standard reply to a vulnerability submission," he said in an e-mail interview. Dai Zovi said he has reported at least eight security vulnerabilities to Apple and has had "nothing but positive interactions" with the company.

(Nancy Gohring in Seattle contributed to this report.)

IDG News Service

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Free stuff

Win an Amazon Kindle!
This month's giveaway gadget - Amazon's Kindle - will keep you entertained on the long trip home to visit family and friends over the holidays. Enter the drawing now!

Applied Security Visualization
By Raffael Marty
Published by Addison-Wesley Professional
Learn more!

 

IT Manager's Handbook
By Bill Holtsnider and Brian D. Jaffe
Published by Morgan Kaufmann
Learn more!

 

Windows Vista Resource Kit
By Mitch Tulloch, Tony Northrup, and Jerry Honeycutt
Published by Microsoft Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources